Improper control of a resource through its lifetime in Mozilla Firefox - CVE-2022-22755
Published: February 8, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way XSL documents are handled by the browser. A remote attacker can trick the victim to load a specially crafted XSL document that can continue JavaScript execution within the bounds of the same-origin policy even after the browser tab is closed.
Affected software
Gentoo Linux
Ubuntu
openEuler
firefox
firefox-debuginfo
firefox-debugsource
mozilla-crashreporter-firefox-debuginfo
firefox (Ubuntu package)
How to mitigate CVE-2022-22755
firefox - update to 79.0-16
firefox-debuginfo - update to 79.0-16
firefox-debugsource - update to 79.0-16
mozilla-crashreporter-firefox-debuginfo - update to 79.0-16
firefox (Ubuntu package) - addressed in versions 97.0+build2-0ubuntu0.18.04.1, 97.0+build2-0ubuntu0.20.04.1, 97.0+build2-0ubuntu0.21.10.1